Grindr user data has been for sale for years
wsj.com
wsj.com
Sex is still considered taboo in many parts of the world and some parts of the US.
Now this, we have them using the Facebook API and them knowing every time I open the app (or did).
I have made every choice I can to reduce the privacy invasion that these companies engage in, but there are simply no alternatives for this one. I would be very surprised to find out that Scruff is actually any better.
The web based ones are likely far far worse.
I hate that this has become normal so much.
And honestly, I think it's necessary.
Of course there is an opposition that believes this hinders digital development in Europe, which is quite slow or nonexistent, but that is also often caused by said opposition itself instead of privacy laws. Because the few digital experts need all their energy in fighting their ideas and corruption.
I think I'm hardly making an original argument, but a big problem is binding Compute and Data, so companies have an incentive to hoard as much data as possible and keep it hostage. Feels like deep down that's the whole valuation of Silicon Valley
Honestly I should look to see if there's places that are working on privacy preserving metrics systems and apply.
But in the end, IMHO what really needs to happen is to enable full data ownership. The semantic web, there was also another project by Tim Berners Lee...
Match owns almost all of the dating-app market, and they have extremely deep pockets to buy/extinguish competition with.
Because of the consolidated nature of the market, and the winner-takes-all nature of the industry, I really believe that it is impossible for a new entry to gain popularity and focus on hard problems like security.
This is fundamentally a problem with capital allocation and incentives. There's not much that a small team can do about it.
But this is a conscious choice. A small team should not need to make the decision to do something like this.
Also Grindr or Scruff isn't exactly small and have a fairly devoted base that doesn't end just because they get into a relationship.
Dating apps also suck at giving compelling reasons to pay them unless the app is purposefully made worse so they can sell the functionality back.
We have 10+ years of Google, Facebook, and others handing out major tools and functionality for free because of the privacy invasion.
I have to wonder how things would have looked had that not become the norm.
As far as being purposefully made worse, yeah both apps do that. Grindr charges $100, Scruff charges $120 a year. Considering how popular both apps are I have to assume they are pulling in quite a bit of money.
At least in the US, one might imagine this is more important to users than hiding their sexual preference.
I'm not sure I agree, though. In an open relationship it'd be no surprise to my partner if I were using Grindr (he probably would be too, in that case!) and I think therefore that'd be more or less orthogonal to the concern around the risk of forcible outing posed by Grindr's misuse of data. Both are certainly of concern, but I think independently so.
Well, they can. New entrants to the dating app market always start out this way. They gain loads of initial trust and word of mouth growth by putting users first. But they inevitably fall victim to the same market forces as their competition, and slowly become the same thing. It happened to Tinder, it happened to Bumble, and it will happen to Hinge.
I'm sure that can't be what you are trying to say - although, if it is, I can certainly understand why you made a throwaway to say it.
This thread reads to me as there may be perverse incentives due to nature of dating and capital markets that make it nearly impossible to compete while valuing security.
It’s an observation that market conditions seem to disadvantage anyone who DOESN’T do that, so unless you like spending a bunch of effort and time (and being less competitive overall because of it, and likely go nowhere), maybe spend your effort somewhere else if you don’t like to be that way.
There are a ton of markets like this. If you wanted to open a ‘good’ check cashing place for instance, go right ahead. Just don’t be surprised if you lose your shirt trying it by not being like the other, less scrupulous players.
The incentives are broken, and telling the people who point out that the incentives are broken that they're just making excuses for bad behavior doesn't actually fix the incentives.
We all want our data to be handled securely, and we should try to understand why that does not happen.
No one has to make a dating app. I don't see how "no one else could do it without betraying their users either!" as you argue - and, again, even granting this is true, which you've done nothing thus far to show - excuses the actual betrayal that actually has occurred. If you'd like to make an argument that it does, I'd be interested to hear that.
So, sure, the one comment to which you've directly responded here, I'll call that out of line on my part. Everything else I've said throughout these comments stands.
It's a comment about dating apps, not about people who decided not to go into dating apps i.e. found "a market you can address without doing that."
And there always will be someone trying the unscrupulous approach, no matter how many people decide not to.
Sounds like a business opportunity.
>Match owns almost all of the dating-app market, and they have extremely deep pockets to buy/extinguish competition with.
Match owns almost all of the dating app market because they've acquired who? Startups who created popular apps in a crowded marketplace that they don't already own.
Now, if you want to argue that you cannot create a popular app in a crowded marketplace without accepting a buyout offer from the dominant player, now that's a topic I think is worth quite a bit of discussion.
People still use Grindr a ton even though these security issues have been well known for years and in most areas users have real concerns for their safety and lives if they’re caught using it, so I can’t say they’re wrong.
It is actually what I would expect from a dating site. Match group apps look more like a vehicle that only exists to transfer money from your pocket into theirs.
understood. the only practical response to the banal corporate indifference of modern markets is ultraviolence. establish a rival dating app and send ninjas to the bedrooms of match owners to threaten their lives
hn says "there's not much a small team can do about it" but they are clearly considering only a small team of technologists and a few salespeople/growth marketers. hn has drastically discounted the impact a small team of (kunai-wielding, not mid-2010s startup recruiter speak) ninjas can have
I really don't trust any of them (App or Website), enough so I have seriously contemplated getting an iPod touch or something and tethering anytime I want to use them. But I have not quite gone that far yet.
There are certain conveniences the apps get you.
Facebook and Google have become very good at tracking you across the web. Sniffles has ads (admittedly all of them are to sign up for premium but I don't know how those ads are served... I have not looked).
So add in google fonts or some other tracking mechanism and suddenly you have a ton of data to tie someone too a website that is meant to be anon. (more or less, I know its not quite that simple but I don't think being on the web makes it necessarily any better)
Gay sex is still illegal in 71 countries in the world. Many of them still have the death penalty
https://76crimes.com/76-countries-where-homosexuality-is-ill...
It's extremely sad how homosexuality is criminalised in such a large part of the world and it makes leaks of Grindr even more dangerous than just for the prospect of blackmail or just exposure.
First of all, we need to stop characterizing it as some kind _emotional_ thing like "love". It is not an emotional thing. It's a real thing.
But I changed my comment as it was not my intention to offend. On the contrary. Just saying "homosexuality" sounds distant and clinical so I said love to make it feel more real. Because really that's what it's about isn't it? For me love is what makes a relationship real. One based on just sex isn't, at least not to me.
Why would something emotional not be real? Sexual attraction is a big part of love but I think the term goes much further than that.
I've heard that some American religions try to 'fit' gay feelings into their principles by telling members it's ok to feel but not to act. Perhaps this is the reason for this sentiment? That by saying "love" I subscribe to the idea that only the physical act makes it 'real'? I find that concept very strange. As if the act is more real than the feeling of love or attraction for someone. For me it's the opposite.
In any case I changed it because I was clearly expressing a sentiment I didn't want to convey. Thanks for pointing it out.
It doesn’t make these laws less regressive, but it does (in most cases) somewhat limit the scope of the laws.
The average case is quite bad, but I wouldnt generalize it to quite every app. Scruff, for example, does take privacy seriously - both in rhetoric and in their user-visible design decisions.
That's not to say there might not be vulnerabilities (which could be said about any company or service), but they don't treat it as a secondary priority.
Grindr, on the other hand, is actively malicious with how aggressively it sells and/or exposes user data willfully.
But I just take Scruff's words with a grain of salt at this point. There is so much that they can do server side that we can't block.
A big part of me thinks it is just inevitable until something like this comes out about Scruff. I don't want to think that... but we have been burned way too many times by apps. Look at what came out about several mental health apps a few days ago.
These B-tier social networks deserve a lot more attention & scrutiny from security researchers.
Are. You. Fucking. Kidding me?
Grindr must’ve been started by the gay community, yeah? Why the hell are we doing this to ourselves?!
The silver lining here is finally an argument for privacy that has very little risk of being shut down as "hypothetical", which is always a dead end for most low-key privacy debates.
That question is harder to answer if you adhere to identity politics and easy to answer if you apply https://en.wikipedia.org/wiki/Classical_Marxism
Seeing that someone is 100 ft away is a common start of a conversation. Maybe they live in the same apartment, at a local coffee shop, work in the same building. Which leads to... well...
That doesn't excuse the privacy issues though.
The types of people that open with "I'm 50m away from you" are super freaking creepy.
Pretty sure SafetyNet, or something like it, from Google will also tattle on you if you spoof your location in apps that don't want you using mock locations, preventing you from using mock locations at all with apps.
down-low, we have an emergency
I use it with microg myself but I have to use a special fork. I wish microg had this option too, it would be great to be able to feed garbage.
"I'm not based in [your city], I just change the location to talk to new people". It's frequent enough that I stopped using the app altogether. OKC was already going downhill well before this.
It takes a few seconds and they are really upfront about it. I can imagine OkCupid charging for such a filtering feature, but I've never paid for it just didn't seem "worth it". Especially since Match.com owns it, and I'm not really helping the underdog.
( I understand that I might not have been making a sensible economical decision, as I have many examples of not doing that in the past )
I've seen some fun papers of "Well, you could do this awful thing..." (comparison of accelerometer data to deconflict which nearby phones are in the same vehicle vs separate ones to better refine social graphs), in addition to all the stuff we know is being done (ultrasonic signals in various ads, tracking shoppers by their wifi/bt beacon MACs, etc). I assume the state of what's actually being done is far worse than what's in the papers, because someone, somewhere, though they could get a signal out of something.
Trying to "de-evil" this sort of system is, first and foremost, fiddling around the edges of what's possible (I expect various people are reading and thinking, "Oh, you think spoofing GPS will matter, cute!), but it's also remaining in the ecosystem that has, repeatedly, demonstrated that they're going to get their paws on everything they think they can justify, and then expand that over time.
There's no reason that a TV needs to be doing automatic content recognition on various inputs, but they're all doing it these days.
I've given up and I no longer carry a smartphone. I'd encourage those who can get away with it to do the same thing. You can't go hoovering up all my data from a dumber KaiOS device because it doesn't run all the apps, and if a company makes their desktop/laptop interface so painful to use to drive people to the phone interface, well, they're probably doing things I don't want to support anymore.
Trying to "reduce the harm" of smartphones, more and more, feels like trying to figure out how to mitigate the impact of a world class meth addiction by focusing on the symptoms - "Oh, you need to hydrate better!" "Here's some skin moisturizer and a toothbrush!" and so on - without ever stating that the problem is the meth and that you need to stop using that, not try to figure out how to avoid losing your teeth while doing it.
He says whilst posting from his phone …
Part of my reason for not carrying a smartphone anymore is to be a better example to my kids, and I certainly point out couples staring at his-n-hers smartphones at a restaurant instead of actually enjoying each other's company.
Odds are good that instead of a smartphone, my daughter will just end up with her HAM license and a VHF handset instead. It'll cover the common cases direct simplex if I put a base station on the house, and my wife isn't opposed to getting her license either. :)
I think a comparison that does it more justice is to the use of leaded gasoline and its downstream effects on crime rates.
Handovers can be signalled by the network or the handset, but they use the received signal quality and strength (and handsets can send their signal quality and strength to the network to facilitate better handover scheduling) to arrange handovers.
You can also triangulate devices effectively using just the cellular signal to them, if you are the mobile network operator, using signal strength, or other techniques like time difference of arrival, if you have good clock sync across your base stations.
> What the WSJ describes would not be possible with our privacy practices today, practices we proactively implemented two years ago
> Grindr takes the privacy of its users extremely seriously, and we have put privacy before profit
> Grindr does not share users’ precise location, we do not share user profile information, and we do not share even industry standard data like age or gender
Gee, I wonder if the advertiser can take a guess.
*some people may identify with some of those, some overlap, some without calling their gender either. It's a large spectrum.
Advertising targeting is broken up by male and female generally.
I'm a gay male and use Grindr
As a general rule, all allegations that aren't specifically denied are true.
For instance "we aren't sharing precise location" = "we are sharing location data with an undisclosed level of reduced precision"
At least according to them, it's more accurate to say "Had been for sale for years". They say they've put a stop to it.
And it was cool the first time, with mountain peaks, and a very accurate compass, going on a hike and figuring out where you were on a map, without the whole satellite cakewalk.
But all of that's a nitpick of a nitpick, you and the parent post are totally right. But like totally. You should all have read the last paragraph in this post first, what I said doesn't change things, it's trivial to get our positions.
Not for myself - because I’m out - but because the fact that I am out would potentially be for sale, and - for instance - my primary partner - isn’t.
She comes from such a traditional family, and her home country is so anti-queer - that if they somehow found out her parents would literally likely commit suicide - the exact same thing happened to a friend of hers, and it’s unfortunately a very real concern.
This marks the official crossing of the line from any potential ‘if you don’t have anything to hide, why do you care’ bullshit excuse that fucking idiots use to push privacy issues aside.
If you are not out - it is not okay for ANYONE you don’t know to know you’re gay/lesbian/bi/whatever.
This is a brutal fucking outrage. I’m frankly fuming, like - on the verge of an anxiety attack - over this.
Lawsuits had better fucking ensue.
Frankly, this makes me want to preemptively leave HER (the lesbian equivalent of Grindr) - before I find out the same shit is happening.
Die, Grindr. Fucking die.
As a queer person this may be the single greatest abomination I’ve seen a corporation claiming to support the LGTBQ+ community commit.
"they" in this case is the family finding out and the family committing suicide? or did "they" change mid-sentence. Sounds bad for any party finding out, just trying to understand the threat model here. If your primary partner found out about the widely reported data leak existing and becoming suicide sounds now extremely probable. The other possible readings of that sentence are, extreme, but less extreme in probability.
Just a couple readings of this that aren't clear.
Just wait a few months, something else will probably show up. Remember that "claiming to support the LGBTQ+ community" is, in almost every case, just a calculated way to increase their profits. Change a few logos, let the PR department fund a float, and wait for the additional dollars to roll in!
> Frankly, this makes me want to preemptively leave HER (the lesbian equivalent of Grindr) - before I find out the same shit is happening.
Good. Do it. The entire core of our modern consumer tech ecosystem is based around this sort of deception and lying. If it's a popular app, it's making the money on the backend somewhere. Robinhood (the stock trading app) was literally just selling off order flows to the high frequency traders who would pay them rather obscenely large sums of money for the "Heyo, I've got someone ready to buy 15 shares of GME, I'm going to buy 15 shares of GME now, and... buy!" data. They existed to sell out an audience who didn't know better for fractions of a cent per trade, but in volume.
If you don't mind some dense reading, Zuboff's book on Surveillance Capitalism is well worth the read. The author is just in love with high scoring Scrabble words for no good reason, unless she finds a reason to invent a new word instead. But the outcome of it is that you'll want to regularly frisbee your smartphone across the room into the nearest wall without a case.
"Modern consumer tech" is absolutely, 150%, at odds with any concept of personal privacy. And the more people start opting out, the sooner we can go back to "My personal habits are not your profits."
But there are some precautions one could take to reduce the risks. Like turning off precise location for specific apps is possible in iOS. I assume similar feature is available in android too. This might not help much in a big densely populated city but in a small city this is good enough to find people on Grindr. I also turn off the location access for Grindr once I favorite some people I like to keep in touch with.
What I really wonder is whether disclosure of these sorts of leaks is selective. I suspect it is. The point being that in showing one or 2 cases, and then showing the system taking a retrospective action, gives the impression that we are being protected. I suspect that grindr has been selected as a sacrificial lamb (of little consequence - eg its not tinder) - and will possible be put through some legal process and appear to be made an example of.
If so, the news will have some headlines, and it will appear that the governance process is doing its job.
I don't think we are being protected though - it would be easy to pass legislation that made these sorts of actions illegal. What is being protected is the reputation of those businesses undertaking the collection. The cost is that we are kept in ignorance of how bad and systemic the situation really is.
the future of firewalls will be keeping your data in is my bet...
i suspect that there will probably be some cool research projects that try to embed identifiable watermarks in behavioral data and then attempt to detect them in purchasable data or data products and/or realtime behavior of ad companies.
It’s not just niche, like a Christian dating app.
If I am a Christian - frankly - living in North America - I’ve got nothing to hide to anyone, mostly.
I probably came from a Christian family, and - if I didn’t - being Christian isn’t something that frankly carries the stigma that being gay/trans/lesbian/bi/etc, does.
I would know, because I happen to be Christian, transgender, and lesbian. :P
There’s an argument that with privacy ‘if you have nothing to hide, why do you care?’ - and being on the LGTBQ+ spectrum nukes that argument, just as being a stoner in a weed-hating state might.
Selling the orientation of individuals for profit is an abomination of capitalism, such a risk to the queer community, and such a fundamental and brutal rape or privacy, that I frankly hope to see a class action lawsuit over this.
Grindr shutting down completely would not be good enough; here. This is beyond felonious. This is a human rights violation of the utmost degree.
Why openly disclose your sexual preference/orientation so eagerly on hacker news comments, then?
If I use a dating app that promises it will maintain its data about my orientation as confidential, and that app turns out to have been lying all along, then I'm forced to run the risk no matter whether I would have chosen to do so. Because I can't know who is accessing that data or what they're doing with it, I don't even have a way to know how much risk I've been forced to take on. And because I have no way to remove my information from the dataset, I don't have any control over how long that risk continues to be present; I have to assume it's forever, or at least as long as a copy still exists.
It's a good example in microcosm of all the issues around handling sensitive data that this industry has had ever since anyone began trusting us with such data in the first place.
The Holocaust, through computerized processing of census data (via IBM), found "Jews" who didn't even know that their maternal grandmothers were Jewish. Comparing those primitive records and tech to today is like comparing Hiroshima to the nukes of today. If some US administration 20 years from now decided that they wanted to round up all of the communists, homosexuals, and Jews with a 90% certainty, even assuming technology hasn't advanced an inch in the interim, they could get the list within days. I think it would be easy even if we turned off the data spigots today and 20 years from now they only had access to data collected between the dawn of web 2.0 and now.
That goes double when we're discussing an issue that goes to the heart of how we as an industry conduct ourselves - to what standard we hold ourselves and one another.
Granted, right now no such standard exists. I don't think that will always be true; if we don't regulate our own behavior then someone will certainly do so for us. I think it'd be a good idea if we had a say in how it happens, and when we have people apparently arguing that no one should expect anyone to hold us to any standard, it's very hard for me even to imagine an argument in support of the idea that we deserve one.
I'd also like to think that, by being in this industry, we're not all in the position of an RJR or Philip Morris employee trying to believe we aren't really peddling addiction and cancer. Whether that sort of thing bothers anyone else, it's not up to me to decide, though I think it should. It does bother me.
I ask this because "human rights" is a wide and varied collection of thoughts and ideas ranging from the right to not be sexually assaulted to the right to not have businesses you interact with sell data about your sexual behaviors.
My point is, the whole conversation is subjective. You're both wrong in the eyes of some people and completely reasonable and correct in the eyes of others. Just some helpful framing you might want to use before "whatabouting" when people's lives may literally be on the line for this information being disseminated in their home countries.
From the safety of my home in an exceedingly liberal state in the US, working for an employer with a decent track record for inclusivity, I would be Big Mad if my grindr data was sold. From Chechnya, I would be terrified for my safety, physically as well as at a job, in the same situation.
TL;dr- When people stop being hate-crimed or state-santioned-murdered for being gay, the community will stop "overreacting" to people outing us against our wishes.
And I'm pretty sure that if we follow the argument to absurdity, all of us should only be talking about a single incident at a time. The worst one, that renders the rest not only irrelevant but disrespectful and insulting to the real victim.
This is also not a hypothetical situation -- something quite similar happened in Egypt a few years ago [1]. And that was using good old fashioned entrapment. The damage could have been far more significant with large-scale data analysis.
While I can't speak for OP: they likely feel comfortable posting about their gender/sexuality on here because they live in a place where that won't happen. And while HN is often less than progressive on LGBT issues, users here generally aren't calling for public executions. But not everyone lives in the US or Western Europe, and these people live under a genuine threat of death.
[0] https://en.wikipedia.org/wiki/LGBT_rights_in_Saudi_Arabia
[1] https://www.independent.co.uk/news/world/middle-east/egypt-l...
Really? I shouldn't have to explain this, but that it's my choice makes all the difference?
Furthermore, if you'd read my comment - it said that I myself am not concerned with disclosing my orientation/gender online - but I am deathly concerned for my fellow queer folk for whom that is not the case.
Some dude did exactly this with tinder and got precise location. Iirc they mitigated by using grids after that, and precision is only accurate to a specific tile. However, a fixed tile size will anonymize you only as much as population density allows. If you're in a rural area, you'll likely be pinpointed.
At least the last time I checked it out, which was the day before I interviewed there. Were I working there, and found this out, I would no longer be working there.
They just assign you to various buckets and then aggregate the information in those buckets to sell targeted advertising.
But they don't sell your data :)
At this time, it's best to assume apps with trackers embedded (you can check that with Aurora Store) sells data associated with you indirectly.
But no it's not as bad as just selling the raw data.
This isn't what was said. What was being said is that the people who claim that they don't sell your data have such complex ways of still selling your data while being literally truthful that there's no way to confidently evaluate risks no matter what they say.
edit: I mean, do you know for certain that a determined attacker can't bulk unmask Google or Facebook users through skillful monitoring of ad auctions and specific ad placements?
If I purchase your location data I can use that to hire a hitman and whack you at home. If I purchase an ad for everybody that lives in NYC they get to see an ad.
---
Regarding if somebody can accumulate ads to derive user data. I mean anything is technically possible but an ad provider doesn't want user data to leak because it lowers the value proposition of their ad exchange
Is that true? Being able to deanonymize targeted individuals or small groups doesn't really cut into a platform business, it's only a concern if you can do it at scale to meaningfully reconstruct their dataset. Sure, they'll work prevent the latter, but does it justify the costs of ensuring the former can't be done? Better targeting sells ads, privacy/security is a cost center.
I'm also not sure how you're going to develop a process to deanonymize an individual that can't just be generalized to create large groups. Like just buy a dataset on people in the US and then run your process using all of them and you can make a large group then.
There doesn't seem to be much information out there though but there are efforts to prevent the site from learning what ad is being displayed and the ad buyer from learning where and who is watching. I think most of this is just done via the iframe that an ad is displayed within.
I would say the ad exchanges could just double dip and serve ads and sell user data if it wasn't an issue but FB did that and ended up with a big hassle from it. So it may be a marketing advantage for Google & Apple to be able to claim they don't sell user data.
They're all written in the, "Well, technically, our lawyers claim we're not lying..." style. But they're sure not end-user friendly, which is the exact point.
And any time they claim they're not doing something explicitly, look for ways they might have navigated around it carefully. Roku's "you agree to let us do anything we want" policy, for instance, includes a dutiful agreement to not do anything prohibited by the laws of the country your data is stored in. Of course, they then later state that they can move your data to any country they want.